At a Glance
- Tasks: Build and maintain automated security solutions for software development at Bloomberg.
- Company: Join Bloomberg, a leader in financial information and technology.
- Benefits: Competitive salary, diverse culture, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on innovation and collaboration.
- Why this job: Make a real impact on software security while working with cutting-edge technologies.
- Qualifications: 3+ years in software development with strong programming skills.
The predicted salary is between 60000 - 80000 £ per year.
Our Team: Bloomberg is building the world’s most trusted information network for financial professionals. We protect Bloomberg. We partner with internal departments to ensure the confidentiality, integrity, and availability of Bloomberg systems and the data we process. We aim to ensure that our clients see us as a trusted partner. Our Chief Information Security Office (CISO) owns the technical aspects of this mission by ensuring Bloomberg products, systems, networks and commercial applications are built and maintained with security in mind.
What's the role? We are seeking a Product Security Engineer to help ensure that Bloomberg software is built securely. You will be responsible for building and maintaining automated security capabilities across the software development lifecycle. You will also engage with engineering partners to provide remediation guidance and enhance security testing to deliver high-fidelity, actionable results. As a member of the Product Security Enablement team, you will help provide automated security testing solutions for Bloomberg, including SAST, DAST, SCA, Secret searching and LLM-based assessments. Our team’s goal is to create preventative security capabilities that integrate into development pipelines and help detect issues early in the software development lifecycle.
An engineering skillset is required for this role. You will be responsible for prototyping new tools, integrating security testing tools and capabilities into the software development lifecycle, and developing custom security capabilities to deliver scalable testing solutions to our engineering teams. This role will routinely challenge your technical background and critical thinking. You will be expected to collaborate with different stakeholders in a fast-paced environment across many technology stacks and services.
We'll trust you to:
- Partner with engineering stakeholders to understand Bloomberg’s development landscape and security needs.
- Develop automated security solutions that integrate into development pipelines.
- Maintain and enhance existing security automation processes and security capabilities.
- Understand and research technical details of core technology stacks and develop or enhance custom code analysis queries.
- Communicate vulnerability landscape and work on mitigations with stakeholders across the business.
- Actively monitor the latest news and trends in automated security capabilities, secure development, and AI-assisted security workflows.
- Develop and enhance operational runbooks.
- Perform ad-hoc vulnerability discovery, including code review and static analysis for key engineering teams, applications and services.
- Build or adopt new security capabilities to address issues at scale, such as Software Composition Analysis, Secret searching, and other automated security testing techniques.
- Use LLMs and AI-assisted workflows as part of security assessments, vulnerability research, secure code review, developer enablement, and security automation.
- Explore, evaluate, and build automation using modern LLM tooling and integration patterns, including custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, and integrations with development and security tooling.
You’ll need to have:
- A strong core engineering background with a proven track record.
- 3+ years of experience in software development.
- Strong programming experience, with working knowledge of at least one of: C/C++, Python, JavaScript/TypeScript.
- Knowledge and experience with DevOps and software used in development pipelines (e.g. Github, Jenkins).
- Working knowledge of build systems, package managers, and development tooling (such as cmake, npm, maven, gradle etc).
- A core understanding of common security vulnerabilities, such as OWASP Top 10 issues and language-specific vulnerabilities.
- Experience using, evaluating, or building with LLMs or AI-assisted tooling in technical workflows.
- Ability to combine technical knowledge with an understanding of core aspects of an information security program.
- Motivation to keep up with latest trends and techniques in the information security community.
- Excellent written and verbal communication skills.
We’d love to see (not required, but nice to have!):
- Experience or familiarity with running, maintaining, and customizing static analysis security testing tools such as CodeQL and Semgrep.
- Broad familiarity with programming language ecosystems and frameworks, particularly C++, JavaScript/TypeScript, Python, Java as well as well as modern systems and infrastructure languages such as Go and Rust.
- Experience using LLMs or AI-assisted tools for security assessments, vulnerability research, secure code review, developer enablement, or security automation.
- Familiarity with LLM automation concepts and tooling, such as custom skills, MCP servers, agentic workflows, retrieval-augmented workflows, or integrations with development and security tooling.
- Knowledge of open source software component management, Software Composition Analysis, and related security tools.
- Knowledge of core concepts in public cloud providers such as AWS, GCP, and Azure.
- Familiarity with container orchestration technologies such as Kubernetes and Docker, and cloud deployment orchestration.
- Technical information security certifications, such as CISSP, CSSLP, or SANS certifications.
- Prior experience integrating security testing into DevOps pipelines.
If indicated, please note that years of experience are a guide; we will consider applications from all candidates who can demonstrate the skills necessary for the role.
Discover what makes Bloomberg unique - watch our for an inside look at our culture, values, and the people behind our success. Bloomberg is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law. Bloomberg is a disability inclusive employer. Please let us know if you require any reasonable adjustments to be made for the recruitment process. If you would prefer to discuss this confidentially, please email amer_recruit@bloomberg.net.
Product Security Engineer - Software Security Enablement London, GBR Posted today employer: Bloomberg L.P.
Bloomberg is an exceptional employer, offering a dynamic work environment in London where innovation and collaboration thrive. With a strong commitment to employee growth, Bloomberg provides opportunities for professional development and encourages a culture of diversity and inclusion. As a Product Security Engineer, you will be at the forefront of securing cutting-edge technology while enjoying the benefits of a supportive team and access to the latest tools and resources in the industry.
StudySmarter Expert Advice🤫
We think this is how you could land Product Security Engineer - Software Security Enablement London, GBR Posted today
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Bloomberg L.P., love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Bloomberg L.P.
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Bloomberg L.P.. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Product Security Engineer - Software Security Enablement London, GBR Posted today
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Bloomberg L.P. insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Bloomberg L.P. that you’re committed to staying ahead in the game.
How to prepare for a job interview at Bloomberg L.P.
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Bloomberg L.P. to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Bloomberg L.P..
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.